Types of pentest
Pentests are defined by what is tested: external infrastructure exposed to the internet, the internal network, web applications, APIs, mobile apps or cloud environments. They are also defined by how much information the testers receive in advance: black box (none), grey box (some, such as user credentials) or white box (full access to documentation and code).
Pentesting vs vulnerability scanning
A vulnerability scan is automated and lists known weaknesses. A pentest is carried out by people who confirm which weaknesses can actually be exploited, chain them together and show the real impact. Both are useful, and they answer different questions.
What a good report includes
A pentest report describes each finding, its severity, how it was exploited and how to fix it, with priorities based on real risk. A retest confirms that the fixes worked.
Where it shows up in compliance
Regular technical testing is expected under ISO 27001, the ENS, NIS2 and SOC 2. DORA requires resilience testing and, for some financial entities, threat led penetration testing (TLPT).




